Thursday, February 18, 2021

Closer.

https://arstechnica.com/tech-policy/2021/02/virginia-is-about-to-get-a-major-california-style-data-privacy-law/

Virginia is about to get a major California-style data privacy law

… If adopted, the Consumer Data Protection Act would apply to entities of a certain size that do business in Virginia or have users based in Virginia

… Legislatures in several other states—including Minnesota, New York, North Dakota, Oklahoma, and Washington —have some kind of data privacy bills currently under consideration.



(Related)

https://www.pogowasright.org/broad-new-data-privacy-legislation-supported-by-florida-governor-and-house-speaker/

Broad New Data Privacy Legislation Supported by Florida Governor and House Speaker

Hayden R. Dempsey and Kate Black of Greenberg Traurig, LLP write:

On Feb. 15, Gov. Ron DeSantis and House Speaker Chris Sprowls held a press conference to announce their support for legislation that would significantly increase data privacy and security regulation and create new rights for Florida consumers with respect to their personal information (PI).
House Bill 969 by Rep. Fiona McFarland (R-Sarasota) would apply to any for-profit business that collects PI about Florida residents and satisfies one or more of the following thresholds: (a) has annual revenue over $25 million, (b) collects 50% or more of its revenue from selling or sharing PI, or (c) sells or shares the PI of 50,000 or more consumers or devices. If passed, the law will take effect Jan. 1, 2022.

Read more on National Law Review.





Probably not the answer, but likely one component.

https://www.zdnet.com/article/defence-lists-cyber-mitigation-as-key-factor-for-building-ethical-ai/

Defence lists cyber mitigation as key factor for building ethical AI

The Australian Department of Defence has released a new report on its findings for how to reduce the ethical risk of artificial intelligence projects, noting that cyber mitigation will be key to maintaining the trust and integrity of autonomous systems.

The report was drafted following concerns from Defence that failure to adopt emerging technologies in a timely manner could result in military disadvantage, while premature adoption without sufficient research and analysis could result in inadvertent harms.

"Significant work is required to ensure that introducing the technology does not result in adverse outcomes," Defence said in the report [PDF].

… In the report, participants have jointly created five key considerations – trust, responsibility, governance, law, traceability – that they believe are essential during the development of any ethical AI project.





Get out there and do something?

https://www.brookings.edu/research/strengthening-international-cooperation-on-artificial-intelligence/

Strengthening international cooperation on artificial intelligence





I am curious to see the reaction. Facebook users will notice, but will news organizations care?

https://www.makeuseof.com/facebook-bans-news-australia-over-proposed-legislation/

Facebook Bans News in Australia Over Proposed Legislation

… Facebook previously cut a deal with the UK and agreed to pay news publishers, which is why it's surprising that Facebook wasn't able to do the same in Australia.

Facebook's ban on news is exactly what it sounds like; the platform will no longer display news articles in Australia. While this might help users escape from constantly hearing about politics or the latest controversy, it could also prove irritating when trying to share a story with a friend or family member.

The ban on news means that no news, whether local, national, or global, will be displayed on the platform. Easton outlined these restrictions in more detail, stating that "people and news organisations in Australia are now restricted from posting news links and sharing or viewing Australian and international news content on Facebook."



(Related) Governments have Facebook accounts too.

https://www.abc.net.au/news/2021-02-18/bom-health-authorities-betoota-caught-in-facebook-news-ban/13166394?section=technology

Posts disappear from pages of health authorities, Bureau of Meteorology amid Facebook news ban

… Some pages that don't fit the traditional news genre were stripped out as part of the stoush between Facebook and the federal government over whether the social media company should pay for Australian content it runs on its site.

In response to the outages, Facebook said government pages should not be hit by the changes. A spokesperson said any inadvertently impacted pages would be fixed.

"As the law does not provide clear guidance on the definition of news content, we have taken a broad definition in order to respect the law as drafted," the spokesperson said in a statement.



(Related)

https://www.platformer.news/p/facebook-calls-australias-bluff

Facebook calls Australia's bluff

Yesterday, I wrote that Australia’s News Media Bargaining Code threatened to splinter the internet. On Wednesday morning, the splintering arrived: Google cut a deal with News Corp. that will ensure its services continue to be provided in Australia, and Facebook walked away from the bargaining table and began preventing people from sharing news links from Australian publishers around the world.

I think Facebook basically did the right thing, and Google basically did the wrong thing, even though Google had a much tougher call to make. Today, let’s talk about why the tech giants made the decisions that they did, why Australia’s shakedown is rotten, and what’s likely to happen next. (If you didn’t read my piece on the subject yesterday, it offers a lot of useful context for what follows. I’ve made it free for all subscribers to read.)





User interface design: too easy to use?

https://arstechnica.com/tech-policy/2021/02/citibank-just-got-a-500-million-lesson-in-the-importance-of-ui-design/

Citibank just got a $500 million lesson in the importance of UI design

Citibank was trying to make $7.8M in interest payments. It sent $900M instead.

A federal judge has ruled that Citibank isn't entitled to the return of $500 million it sent to various creditors last August. Kludgey software and a poorly designed user interface contributed to the massive screwup.

Citibank was acting as an agent for Revlon, which owed hundreds of millions of dollars to various creditors. On August 11, Citibank was supposed to send out interest payments totaling $7.8 million to these creditors.

However, Revlon was in the process of refinancing its debt—paying off a few creditors while rolling the rest of its debt into a new loan. And this, combined with the confusing interface of financial software called Flexcube, led the bank to accidentally pay back the principal on the entire loan—most of which wasn't due until 2023.



Wednesday, February 17, 2021

Securing privacy.

https://www.zdnet.com/article/spy-pixels-in-emails-to-track-recipient-activity-are-now-an-endemic-privacy-concern/#ftag=RSSbaffb68

Tracker pixels in emails are now an ‘endemic’ privacy concern

This week, the Hey messaging service analyzed its traffic following a request from the BBC and discovered that roughly two-thirds of emails sent to its users' private email accounts contained what is known as a "spy pixel."

Spy pixels, also known as tracking pixels or web beacons, are invisible, tiny image files – including .PNGs and .GIFs – that are inserted in the content body of an email.

They may appear as clear, white, or another color to merge with the content and remain unseen by a recipient and are often as small as 1x1 pixels.

The recipient of an email does not need to directly engage with the pixel in any way for it to track certain activities. Instead, when an email is opened, the tracking pixel is automatically downloaded – and this lets a server, owned by a marketer, know that the email has been read. Servers may also record the number of times an email is opened, the IP address linked to a user's location, and device usage.

… In Europe, GDPR demands that organizations tell recipients of the use of such pixels. However, the water has been muddied surrounding the transparency necessary to implement pixel tracking, as consent is not always required – and when it is, this could be 'obtained' automatically when a user signs up to an email service and is asked to read a privacy notice published on a website.

… It is possible to prevent tracking pixels from triggering by disallowing automatic image uploads in your web browser, or by downloading email and browser add-ons to block trackers.





Was this really a bad idea?

https://www.bespacific.com/the-troubling-new-practice-of-police-livestreaming-protests/

The Troubling New Practice of Police Livestreaming Protests

Slate – “This article is part of the Free Speech Project, a collaboration between Future Tense and the Tech, Law, & Security Program at American University Washington College of Law that examines the ways technology is influencing how we think about speech. Last summer’s anti–police brutality protests represented the largest mass demonstration effort in American history. Since then, law enforcement departments nationwide have faced intense scrutiny for how they policed these historic protests. The repeated, egregious instances of violence against journalists and protesters are well documented and have driven widespread calls for systematic reform. These calls have focused in part on surveillance, after the police used sophisticated social media data monitoring, commandeered non-city camera networks, and tried other intrusive methods to identify suspects. [Does participation make you a ‘suspect?’ Bob] But in Oregon, the Portland Police Bureau went a step further in its innovation: It broadcast its surveillance publicly, in real time, by livestreaming protests on social media. According to a lawsuit filed by the ACLU, PPB hosted a video on YouTube and on its official Twitter feed—which has more than 230,000 followers—on at least three occasions. PPB allegedly zoomed in to focus on individual protesters’ faces, making them easily identifiable and vulnerable to surveillance technologies such as facial recognition software, which law enforcement used to identify a protester in D.C.’s Lafayette Square and, reportedly, many of the insurrectionists who stormed the Capitol on Jan. 6. PPB first justified its public livestreaming on the grounds that it was necessary to provide “situational awareness” and to record possible criminal activity, and later “so the community could understand what was occurring at the protest.” But an Oregon court quickly forbade the livestreams, based on Oregon law and a local consent decree…”





If a home owner refused, were there consequences? How could they know in advance?

https://gizmodo.com/the-lapd-asked-ring-owners-to-hand-over-footage-of-blm-1846283117

The LAPD Asked Ring Owners to Hand Over Footage of BLM Protesters

… On Tuesday, digital rights nonprofit the Electronic Frontier Foundation released the results of a Freedom of Information Act (FOIA) request which it had sent to the LAPD. The EFF obtained emails showing that a detective with the LAPD—which has a partnership with Ring’s Neighbors community app— asked for owners of the doorbell cams to submit footage to the “Safe L.A. Task Force” picturing “recent protests.” The timeline of the requests match up with nationwide protests following the killing of George Floyd by Minneapolis police, which drew countless thousands over the course of weeks in Los Angeles.





The implications are at least confusing. Watch the short video...

https://petapixel.com/2021/02/16/ai-can-now-turn-you-into-a-fully-digital-realistic-talking-clone/

AI Can Now Turn You Into a Fully Digital, Realistic Talking Clone

Hour One describes itself as a “video transformation company” that wants to replace cameras with code, and its latest creation is the ability for anyone to create a fully digital clone of themselves that can appear to speak “on camera” without a camera or audio inputs at all.

The company has debuted its digital clone technology in partnership with YouTuber Taryn Southern. In the video above, Southern is a fully digital creation that was created as a collaborative experiment between Southern and Hour One. The company uses a proprietary AI-driven process to provide automation to video creation, which enables presenter-led videos at scale without needing to put a person in front of a camera.





I’m betting that this won’t work either.

https://www.newstatesman.com/science-tech/2021/02/how-prevent-ai-taking-over-world

How to prevent AI from taking over the world

… The best and most direct way to control AI is to ensure that its values are our values. By building human values into AI, we ensure that everything an AI does meets with our approval. But this is not simple. The so-called “Value Alignment Problem” – how to get AI to respect and conform to human values – is arguably the most important, if vexing, problem faced by AI developers today.

So far, this problem has been seen as one of uncertainty: if only we understood our values better, we could program AI to promote these values. Stuart Russell, a leading AI scientist at Berkeley, offers an intriguing solution. Let’s design AI so that its goals are unclear. We then allow it to fill in the gaps by observing human behaviour. By learning its values from humans, the AI’s goals will be our goals.



Tuesday, February 16, 2021

A tool for my Computer Security (and Ethical Hacking) students.

https://www.muo.com/network-secure-analyse-network-traffic-wireshark/

Is Your Network Secure? How to Analyse Network Traffic With Wireshark

Want to learn how to use Wireshark? This guide introduces the core features of Wireshark with real-world examples.

Wireshark is available to download on devices running Windows, macOS, and Linux.





Podcast and transcript.

https://www.sdxcentral.com/podcast/7-layers/7-layers-artificial-intelligence-friend-or-foe/2021/02/

7 Layers: Artificial Intelligence, Friend or Foe?

… In this episode we will cover:

  • What AI is

  • The elements and types of AI

  • AI implementation, supporting technologies, and use cases

  • AI origins

  • The current market landscape

  • And the future of AI





The non-lawyer asks: Could individuals have sued Standard Oil? If the government has opted not to sue is that evidence of Googles innocence?

https://www.nytimes.com/2021/02/16/technology/google-facebook-private-antitrust.html

Big Tech’s Next Big Problem Could Come From People Like ‘Mr. Sweepy’

Google is facing antitrust cases from Europe’s top competition enforcer, the Justice Department and attorneys general from more than 30 states and territories.

Then there are the lawsuits from people like Mr. Sweepy.

The operator of a website called Sweepstakes Today, Mr. Sweepy — a nickname used by Craig McDaniel — says Google used its power over online advertising to bleed his website dry. In December, he filed a lawsuit against Google, saying he was entitled to “substantial” damages.

His case is one of what is expected to be a host of private antitrust lawsuits stemming from the government cases against Google and Facebook.

Already, more than 10 suits echoing the federal and state cases have been filed against one or both of the Silicon Valley giants in recent months. Many of them lean on evidence unearthed by the government investigations. Last month, for example, a media company in West Virginia sued Google and Facebook, arguing that the tech companies had worked together to monopolize the digital ad market. Its lawyers extensively cited evidence from the government cases.





Just because I like lists of sites/services/tools I might use.

https://www.muo.com/tag/9-cleanest-safest-websites-download-free-software-windows/

The 10 Safest Free Software Download Sites for Windows



(Ditto)

https://www.muo.com/tag/programmer-browser-ides/

The 13 Best Browser IDEs Every Programmer Should Know About





In my local library and already on hold. (I like that ‘Library Extension’ in Chrome.)

https://www.nationalreview.com/2021/02/ai-fyi/

AI, FYI

Editor’s Note: The below is an expanded version of a review that appears in the current issue of National Review. The book is A Brief History of Artificial Intelligence: What It Is, Where We Are, and Where We Are Going, by Michael Wooldridge.



Monday, February 15, 2021

Utah is on a roll?

https://www.pogowasright.org/utah-house-passes-bill-to-further-limit-warrantless-collection-of-electronic-data/

Utah House Passes Bill to Further Limit Warrantless Collection of Electronic Data

More positive news out of Utah this week. Mike Maharrey explains:

… the Utah House unanimously passed a bill that would require police to get a warrant before accessing data transmitted through an electronic communication service. The proposed law would not only increase privacy protections in Utah; it will also hinder the expansion of the federal surveillance state.
Rep. Craig Hall (R-West Valley City) introduced House Bill 87 (HB87 ) on Jan 19. The proposed law would prohibit law enforcement agencies from accessing electronic information or data transmitted through a provider of an electronic communication service. In practice, this tightens up the existing law to ensure police must get a warrant before accessing communication service provider networks in order to intercept data.
The proposed law also makes some technical changes to warrant reporting procedures.
On March 5, the House Judiciary Committee approved HB87 by a 7-0 vote. Yesterday, the full House passed the bill with a vote of 72-0.

Read more on Tenth Amendment Center.



(Related)

https://www.pogowasright.org/ut-suspect-has-a-5a-right-to-not-give-up-unlock-code-to-cell-phone/

UT: Suspect has a 5A right to not give up unlock code to cell phone

Defendant had a Fifth Amendment right to not give up the unlock code to his cell phone. Utah declines to apply the foregone conclusion exception to the Fifth Amendment to attempt to require a suspect to give up his cell phone unlock code. The state’s comment on it at trial as an inference of guilt was reversible error. State v. Valdez, 2021 UT App 13, 2021 UT App LEXIS 14 (Feb. 11, 2021)

Read excerpts from the opinion on FourthAmendment.com





Read worthy.

https://www.newyorker.com/tech/annals-of-technology/who-should-stop-unethical-ai

Who Should Stop Unethical A.I.?

In computer science, the main outlets for peer-reviewed research are not journals but conferences, where accepted papers are presented in the form of talks or posters. In June, 2019, at a large artificial-intelligence conference in Long Beach, California, called Computer Vision and Pattern Recognition, I stopped to look at a poster for a project called Speech2Face. Using machine learning, researchers had developed an algorithm that generated images of faces from recordings of speech. A neat idea, I thought, but one with unimpressive results: at best, the faces matched the speakers’ sex, age, and ethnicity—attributes that a casual listener might guess.

… As Hanna argued that voice-to-face prediction was a line of research that “shouldn’t exist,” others asked whether science could or should be stopped. “It would be disappointing if we couldn’t investigate correlations—if done ethically,” one researcher wrote. “Difficult, yes. Impossible, why?”



Sunday, February 14, 2021

Does it take an AI to audit an AI? My AI says, ‘No, trust me.’

https://arxiv.org/abs/2102.04661

Security and Privacy for Artificial Intelligence: Opportunities and Challenges

The increased adoption of Artificial Intelligence (AI) presents an opportunity to solve many socio-economic and environmental challenges; however, this cannot happen without securing AI-enabled technologies. In recent years, most AI models are vulnerable to advanced and sophisticated hacking techniques. This challenge has motivated concerted research efforts into adversarial AI, with the aim of developing robust machine and deep learning models that are resilient to different types of adversarial scenarios. In this paper, we present a holistic cyber security review that demonstrates adversarial attacks against AI applications, including aspects such as adversarial knowledge and capabilities, as well as existing methods for generating adversarial examples and existing cyber defence models. We explain mathematical AI models, especially new variants of reinforcement and federated learning, to demonstrate how attack vectors would exploit vulnerabilities of AI models. We also propose a systematic framework for demonstrating attack techniques against AI applications and reviewed several cyber defences that would protect AI applications against those attacks. We also highlight the importance of understanding the adversarial goals and their capabilities, especially the recent attacks against industry applications, to develop adaptive defences that assess to secure AI applications. Finally, we describe the main challenges and future research directions in the domain of security and privacy of AI technologies.



(Related)

https://link.springer.com/article/10.1007/s43681-021-00039-2

AI auditing and impact assessment: according to the UK information commissioner’s office

As the use of data and artificial intelligence systems becomes crucial to core services and business, it increasingly demands a multi-stakeholder and complex governance approach. The Information Commissioner's Office’s ‘Guidance on the AI auditing framework: Draft guidance for consultation’ is a move forward in AI governance. The aim of this initiative is toward producing guidance that encompasses both technical (e.g. system impact assessments) and non-engineering (e.g. human oversight) components to governance and represents a significant milestone in the movement towards standardising AI governance. This paper will summarise and critically evaluate the ICO effort and try to anticipate future debates and present some general recommendations.





Curious to see how they plan to do this. Do they have a plan? As I read it, the bill simply says “don’t buy, build or use” AI that discriminates.

https://www.geekwire.com/2021/washington-state-lawmakers-seek-ban-government-using-ai-tech-discriminates/

Washington state lawmakers seek to ban government from using discriminatory AI tech

Washington state could become a national leader in regulating the technologies of the future, thanks in part to a bill up for debate that would establish new guardrails on government use of artificial intelligence.

On the heels of Washington’s landmark facial recognition bill enacted last year, state lawmakers and civil rights advocates are demanding new rules that ban discrimination from automated decision-making by public agencies. The bill would establish new regulations for government departments that use “automated decisions systems,” a category that includes any algorithm that analyzes data to make or support government decisions.



(Related) Even non-AI governance is difficult.

https://www.theverge.com/22273071/podcast-moderation-apple-spotify-podbean-steve-bannon?scrolla=5eb6d68b7fedc32c19ef33b4

CAN ANYONE MODERATE PODCASTS?

Apple, Spotify, and the impossible problem of moderating shows





Can they detect my skepticism?

https://venturebeat.com/2021/02/13/thought-detection-ai-has-infiltrated-our-last-bastion-of-privacy/

Thought-detection: AI has infiltrated our last bastion of privacy

… Research published last week from Queen Mary University in London describes an application of a deep neural network that can determine a person’s emotional state by analyzing wireless signals that are used like radar. In this research, participants in the study watched a video while radio signals were sent towards them and measured when they bounced back. Analysis of body movements revealed “hidden” information about an individual’s heart and breathing rates. From these findings, the algorithm can determine one of four basic emotion types: anger, sadness, joy, and pleasure. The researchers proposed this work could help with the management of health and wellbeing and be used to perform tasks like detecting depressive states.





A field to study.

https://books.google.com/books?hl=en&lr=&id=J-IaEAAAQBAJ&oi=fnd&pg=PA155&dq=%22artificial+intelligence%22++%2Bprivacy&ots=_S3k8bTYv3&sig=VZp45-2WOXFoydJy-zCck9cQJK4#v=onepage&q&f=false

AI and Deep Learning in Biometric Security: Trends, Potential, and Challenges



Saturday, February 13, 2021

Hack where the money is...

https://www.cpomagazine.com/cyber-security/identity-theft-doubled-during-the-pandemic-as-fraudsters-targeted-covid-19-relief-payments/

Identity Theft Doubled During the Pandemic as Fraudsters Targeted COVID-19 Relief Payments

The Federal Trade Commission (FTC) says that cases of identity theft skyrocketed during the COVID-19 pandemic, with incidents reported doubling compared to 2019.

Most of the incidents targeted government relief funds reserved for individuals and small businesses hardest hit by the pandemic.

The FTC announced that it recorded about 1.4 million reports of identity theft incidents in 2020, twice the number of cases reported in 2019. About 394,280 incidents were associated with unemployment insurance benefits, compared to 12,900 incidents reported in 2019.



(Related) Here is why hacking is so attractive.

https://www.elliptic.co/blog/jokers-stash-retiring

One of the World's Most Prolific Cybercriminals Has Retired - And May Well Be a Bitcoin Billionaire





Useful backgrounder.

https://www.muo.com/how-the-top-instant-messaging-services-use-end-to-end-encryption/

How the Top Instant Messaging Services Use End-to-End Encryption





For my “History of Security’ lecture.

https://www.schneier.com/blog/archives/2021/02/medieval-security-techniques.html

Medieval Security Techniques

Sonja Drummer describes (with photographs) two medieval security techniques. The first is a for authentication: a document has been cut in half with an irregular pattern, so that the two halves can be brought together to prove authenticity. The second is for integrity: hashed lines written above and below a block of text ensure that no one can add additional text at a later date.





Is a complete ban the proper option?

https://techcrunch.com/2021/02/12/minneapolis-facial-recognition-ban/

Minneapolis bans its police department from using facial recognition software

Minneapolis voted Friday to ban the use of facial recognition software for its police department, growing the list of major cities that have implemented local restrictions on the controversial technology. After an ordinance on the ban was approved earlier this week, 13 members of the city council voted in favor of the ban, with no opposition.

The new ban will block the Minneapolis Police Department from using any facial recognition technology, including software by Clearview AI. That company sells access to a large database of facial images, many scraped from major social networks, to federal law enforcement agencies, private companies and a number of U.S. police departments. The Minneapolis Police Department is known to have a relationship with Clearview AI, as is the Hennepin County Sheriff’s Office, which will not be restricted by the new ban.





How does this work? Google pays off some publishers to avoid paying all publishers? Would Napoleon approve?

https://www.reuters.com/article/us-google-france-copyright-exclusive-idUSKBN2AC27N

Exclusive: Google's $76 million deal with French publishers leaves many outlets infuriated

Alphabet Inc’s Google has agreed to pay $76 million over three years to a group of 121 French news publishers to end a more than year-long copyright spat, documents seen by Reuters show.

The agreement between Google and the Alliance de la presse d’information generale (APIG), a lobby group representing most major French publishers, was announced previously, but financial terms had not been disclosed.

The move infuriated many other French outlets, which deemed it unfair and opaque. Publishers in other countries will scrutinize the French agreement, the highest-profile in the world under Google’s new program to provide compensation for news snippets used in search results.

… The accord follows France’s implementation of the first copyright rule enacted under a recent European Union law that creates “neighbouring rights,” requiring large tech platforms to open talks with publishers seeking remuneration for use of news content.

In Australia, lawmakers have drafted legalisation that would require Google and Facebook to pay publishers and broadcasters for content. Google has threatened to shut down its search engine in Australia if the country adopts that approach, which the company called “unworkable.”





Will they still want to shut down big tech if it is paying their bills?

https://www.nytimes.com/2021/02/12/technology/maryland-digital-ads-tax.html

Maryland Approves Country’s First Tax on Big Tech’s Ad Revenue

… The State Senate voted on Friday to override the governor’s veto of the measure, following in the footsteps of the state’s House of Delegates, which gave its approval on Thursday. The tax will generate as much as an estimated $250 million in the first year after enactment, with the money going to schools.

The approval signals the arrival in the United States of a policy pioneered by European countries, and it is likely to set off a fierce legal fight over how far communities can go to tax the tech companies.

… Bill Ferguson, a Baltimore Democrat who is president of the State Senate, was a main driver behind the bill. He said he was inspired by an Op-Ed essay from the economist Paul Romer proposing taxing targeted ads to encourage the companies to change their business models.